Back to jobs

Software Engineer - AI Security Product

Palo Alto, California, USA

Obsidian Security is a global leader in cyber security protecting the SaaS and non-human identity layer modern enterprises run on — from Salesforce and Snowflake to the AI agents now deployed inside them. The Obsidian Security platform gives unified visibility into every human and machine identity, app, and integration across their SaaS estate, detects identity-based and supply chain attacks in real time, and enforces least-privilege access before it's exploited. Trusted by major Fortune 500 companies T-Mobile, Workday, Snowflake, and S&P Global, Obsidian ranked No. 95 on the 2025 Deloitte Technology Fast 500™, growing nearly 1000% from 2021–2024 — helping CISOs turn an unmonitored attack surface into one they can govern with confidence. Obsidian has also been recognized by Forbes as America's Best Startup Employers in 2026.

In August 2026, Obsidian raised $85 million in Series D financing led by Crescent Cove Advisors, with participation from existing investors including Greylock Partners, Menlo Ventures, Norwest Venture Partners, IVP, Wing Ventures, and GV — pushing Obsidian's valuation to $1.1 billion, crossing into unicorn status. Obsidian is using the funding to deepen its R&D in agentic AI security and extend its platform as the standard for governing what AI agents can access and do inside third-party applications.

With global momentum, a growing partner ecosystem including SentinelOne, Databricks, and Google Cloud, and fresh capital from its Series D behind it, Obsidian is scaling rapidly toward long-term growth and IPO readiness.

About the Role

AI is the fastest-moving attack surface in the enterprise. Copilot, ChatGPT Enterprise, Gemini, Claude, and a wave of agentic tools are being wired into corporate SaaS faster than security teams can keep up — with broad OAuth scopes, opaque data flows, and non-human identities acting on behalf of employees. Obsidian sits directly in the path of this shift.

As a software engineer working on AI Security, you'll define how Obsidian understands, identifies, and mitigates risk in AI and agentic platforms. You'll own the threat models and data modeling that protect customers — and you'll work in the data yourself, because in this space, the security judgment and the query are inseparable.

What You'll Do

  • Develop deep expertise in how AI platforms (ChatGPT Enterprise, Copilot, Gemini, Claude, Glean, agentic frameworks) authenticate, what scopes they request, and where risk concentrates.
  • Research emerging AI attack techniques — prompt injection, tool/agent misuse, RAG poisoning, over-permissioned integrations
  • Prototype and ship highly available AI Agent security products.
  • Build and improve data pipelines for high efficiency, development velocity and low cost.

Requirements

  • 1–3 years of software engineering experience shipping and owning production backend systems, with proficiency in a modern language (Python, Go, or similar).
  • Experience with — AWS/GCP, containers, CI/CD, observability, and production ownership.
  • Hands-on experience with LLM APIs and agentic patterns (tool/function calling, MCP, agent frameworks), or a demonstrated ability to ramp up fast.
  • Hands-on experience with a modern data stack (dbt, and a columnar warehouse or query engine such as ClickHouse, Snowflake, BigQuery, or Databricks).
  • Clear communicator across engineers, PMs, and customer security teams.
  • Comfortable operating with ambiguity in a fast-moving problem space.

Nice to Have

  • Strong grasp of how SaaS platforms (Google Workspace, Microsoft 365, Salesforce, Okta) expose data — APIs, event schemas, permissions, auth flows.
  • Deep knowledge of AI and SaaS security — OWASP LLM Top 10, MITRE ATLAS, prompt injection, agent/tool-use risks, OAuth abuse, and identity models across major AI and SaaS platforms.
  • Experience in building a cybersecurity product.
  • Strong grasp of identity and access control concepts — OAuth flows, scopes, tokens, and non-human identities.

Employee Benefits

Our competitive benefits packages are designed to support our employees' well-being, both at work and at home.  Our US based employees enjoy:

  • Competitive compensation with equity and 401k
  • Comprehensive healthcare with dental and vision coverage
  • Flexible paid time off and paid holiday time off 
  • 12 weeks of new parent or family leave
  • Personal and professional development resources

For more details on our US benefits, or for information on our international benefits, please see here.

Pay Transparancy

Please note that the base pay range is a guideline and for candidates who receive an offer, the base pay will vary based on factors such as work location, as well as the knowledge, skills and experience of the candidate. In addition to a competitive base salary, this position is eligible for equity awards and may be eligible for sales commission or incentive compensation based on the role or function within the company.

At Obsidian, we are proud to be an equal-opportunity employer. We value diversity and hire for talent, passion, and compassion. In compliance with federal law, all persons hired will be required to submit satisfactory proof of identity and legal authorization.  If you have a need that requires accommodation, please contact accommodations@obsidiansecurity.com

Information collected and processed as part of any job applications you choose to submit is subject to Obsidian’s Applicant Privacy Policy.

Base Salary Range

$155,000 - $180,000 USD

Employee Benefits:

Our competitive benefits packages are designed to support our employees' well-being, both at work and at home.  Our US based employees enjoy:

  • Competitive compensation with equity and 401k
  • Comprehensive healthcare with dental and vision coverage
  • Flexible paid time off and paid holiday time off 
  • 12 weeks of new parent or family leave
  • Personal and professional development resources

For more details on our US benefits, or for information on our international benefits, please see here.

Create a Job Alert

Interested in building your career at Obsidian Security? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...
Select...
Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Obsidian Security’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...